100% Pass Guaranteed Accurate Professional-Cloud-Security-Engineer Answers 365 Days Free Updates [Q121-Q139]

Share

100% Pass Guaranteed Accurate Professional-Cloud-Security-Engineer Answers 365 Days Free Updates

Professional-Cloud-Security-Engineer DUMPS Q&As with Explanations Verified & Correct Answers


Google Professional-Cloud-Security-Engineer certification is an exam designed to test the knowledge and expertise of individuals in the field of cloud security engineering. Professional-Cloud-Security-Engineer exam is intended for professionals who have in-depth knowledge of cloud security technologies and methodologies, and who are looking to become certified by Google Cloud as a Professional Cloud Security Engineer.


The Google Professional-Cloud-Security-Engineer exam covers a wide range of topics, including security management, data protection, network security, and compliance. Candidates are expected to have a deep understanding of the security controls and mechanisms available on the Google Cloud Platform. They should also be able to identify and mitigate potential security threats and vulnerabilities.

 

NEW QUESTION # 121
An organization recently began using App Engine to build and host its new web application for its customers. The organization wants to use its existing IAM setup to allow its developer employees to have elevated access to the application remotely. This would allow them to push updates and fixes to the application via an HTTPS connection. Non-developer employees should only get access to the production version without development permissions. Which Google Cloud Platform solution should be used to meet these requirements?

  • A. Disable access for non-developer employees by removing their Google Group from the application access control list (ACL).
  • B. Set up Virtual Private Cloud (VPC) firewall rules to manage authentication and different authorization levels for employee access.
  • C. Synchronize the organization's Active Directory using Cloud Identity for employee access via Cloud VPN.
  • D. Set up Cloud Identity-Aware Proxy (Cloud IAP) to manage authentication and different authorization levels for employee access.

Answer: D

Explanation:
A is not correct because synchronizing your users to Google Identity does not grant any differentiated access to an app engine application.
B is not correct because app engine IAM roles only specify different levels of administrative access to app engine applications in a project.
C is correct because Cloud IAP allows the organization to establish different levels of access based on user criteria for app engine apps.
D is not correct because VPC firewall rules do not grant different levels of authorization and only allow/block traffic.
https://cloud.google.com/appengine/docs/standard/python/access-control
https://cloud.google.com/iap/docs/concepts-overview


NEW QUESTION # 122
A customer needs to launch a 3-tier internal web application on Google Cloud Platform (GCP). The customer's internal compliance requirements dictate that end-user access may only be allowed if the traffic seems to originate from a specific known good CIDR. The customer accepts the risk that their application will only have SYN flood DDoS protection. They want to use GCP's native SYN flood protection.
Which product should be used to meet these requirements?

  • A. Cloud Armor
  • B. VPC Firewall Rules
  • C. Cloud Identity and Access Management
  • D. Cloud CDN

Answer: A

Explanation:
Explanation/Reference: https://cloud.google.com/blog/products/identity-security/understanding-google-cloud-armors-new- waf-capabilities


NEW QUESTION # 123
You want to use the gcloud command-line tool to authenticate using a third-party single sign-on (SSO) SAML identity provider. Which options are necessary to ensure that authentication is supported by the third-party identity provider (IdP)? (Choose two.)

  • A. SSO SAML as a third-party IdP
  • B. OpenID Connect
  • C. Identity Platform
  • D. Identity-Aware Proxy
  • E. Cloud Identity

Answer: A,B

Explanation:
To provide users with SSO-based access to selected cloud apps, Cloud Identity as your IdP supports the OpenID Connect (OIDC) and Security Assertion Markup Language 2.0 (SAML) protocols. https://cloud.google.com/identity/solutions/enable-sso


NEW QUESTION # 124
You are the security admin of your company. You have 3,000 objects in your Cloud Storage bucket. You do not want to manage access to each object individually. You also do not want the uploader of an object to always have full control of the object. However, you want to use Cloud Audit Logs to manage access to your bucket.
What should you do?

  • A. Set up Uniform bucket-level access on the Cloud Storage bucket and manage access for users using IAM.
  • B. Set up a default bucket ACL and manage access for users using IAM.
  • C. Set up an ACL with OWNER permission to a scope of allUsers.
  • D. Set up an ACL with READER permission to a scope of allUsers.

Answer: C

Explanation:
https://cloud.google.com/storage/docs/access-control/lists


NEW QUESTION # 125
A manager wants to start retaining security event logs for 2 years while minimizing costs. You write a filter to select the appropriate log entries.
Where should you export the logs?

  • A. StackDriver logging
  • B. BigQuery datasets
  • C. Cloud Storage buckets
  • D. Cloud Pub/Sub topics

Answer: C


NEW QUESTION # 126
An organization is starting to move its infrastructure from its on-premises environment to Google Cloud Platform (GCP). The first step the organization wants to take is to migrate its ongoing data backup and disaster recovery solutions to GCP. The organization's on-premises production environment is going to be the next phase for migration to GCP. Stable networking connectivity between the on-premises environment and GCP is also being implemented.
Which GCP solution should the organization use?

  • A. BigQuery using a data pipeline job with continuous updates via Cloud VPN
  • B. Cloud Storage using a scheduled task and gsutil via Cloud Interconnect
  • C. Compute Engines Virtual Machines using Persistent Disk via Cloud Interconnect
  • D. Cloud Datastore using regularly scheduled batch upload jobs via Cloud VPN

Answer: B

Explanation:
https://cloud.google.com/solutions/dr-scenarios-for-data#production_environment_is_on-premises
https://medium.com/@pvergadia/cold-disaster-recovery-on-google-cloud-for-applications-running-on-premises-114b31933d02


NEW QUESTION # 127
A company is running workloads in a dedicated server room. They must only be accessed from within the private company network. You need to connect to these workloads from Compute Engine instances within a Google Cloud Platform project.
Which two approaches can you take to meet the requirements? (Choose two.)

  • A. Configure all Compute Engine instances with Private Access.
  • B. Configure the project with Cloud Interconnect.
  • C. Configure the project with Shared VPC.
  • D. Configure the project with Cloud VPN.
  • E. Configure the project with VPC peering.

Answer: A,E

Explanation:
https://cloud.google.com/solutions/secure-data-workloads-use-cases


NEW QUESTION # 128
You are part of a security team investigating a compromised service account key. You need to audit which new resources were created by the service account.
What should you do?

  • A. Query Admin Activity logs.
  • B. Query Data Access logs.
  • C. Query Stackdriver Monitoring Workspace.
  • D. Query Access Transparency logs.

Answer: B

Explanation:
https://cloud.google.com/iam/docs/audit-logging/examples-service-accounts


NEW QUESTION # 129
Your company wants to determine what products they can build to help customers improve their credit scores depending on their age range. To achieve this, you need to join user information in the company's banking app with customers' credit score data received from a third party. While using this raw data will allow you to complete this task, it exposes sensitive data, which could be propagated into new systems.
This risk needs to be addressed using de-identification and tokenization with Cloud Data Loss Prevention while maintaining the referential integrity across the database. Which cryptographic token format should you use to meet these requirements?

  • A. Secure, key-based hashes
  • B. Deterministic encryption
  • C. Format-preserving encryption
  • D. Cryptographic hashing

Answer: A


NEW QUESTION # 130
Your company is using GSuite and has developed an application meant for internal usage on Google App Engine. You need to make sure that an external user cannot gain access to the application even when an employee's password has been compromised.
What should you do?

  • A. Configure Cloud VPN between your private network and GCP.
  • B. Enforce 2-factor authentication in GSuite for all users.
  • C. Provision user passwords using GSuite Password Sync.
  • D. Configure Cloud Identity-Aware Proxy for the App Engine Application.

Answer: B

Explanation:
Explanation
https://docs.google.com/document/d/11o3e14tyhnT7w45Q8-r9ZmTAfj2WUNUpJPZImrxm_F4/edit?usp=sharin
https://support.google.com/a/answer/175197?hl=en


NEW QUESTION # 131
An engineering team is launching a web application that will be public on the internet. The web application is hosted in multiple GCP regions and will be directed to the respective backend based on the URL request.
Your team wants to avoid exposing the application directly on the internet and wants to deny traffic from a specific list of malicious IP addresses Which solution should your team implement to meet these requirements?

  • A. Cloud Armor
  • B. Network Load Balancing
  • C. SSL Proxy Load Balancing
  • D. NAT Gateway

Answer: A

Explanation:
Reference:
https://cloud.google.com/armor/docs/security-policy-concepts


NEW QUESTION # 132
An organization is starting to move its infrastructure from its on-premises environment to Google Cloud Platform (GCP). The first step the organization wants to take is to migrate its current data backup and disaster recovery solutions to GCP for later analysis. The organization's production environment will remain on- premises for an indefinite time. The organization wants a scalable and cost-efficient solution.
Which GCP solution should the organization use?

  • A. Cloud Datastore using regularly scheduled batch upload jobs
  • B. BigQuery using a data pipeline job with continuous updates
  • C. Compute Engine Virtual Machines using Persistent Disk
  • D. Cloud Storage using a scheduled task and gsutil

Answer: D

Explanation:
https://cloud.google.com/solutions/dr-scenarios-planning-guide#use-cloud-storage-as-part-of-your-daily-backup-routine


NEW QUESTION # 133
A company migrated their entire data/center to Google Cloud Platform. It is running thousands of instances across multiple projects managed by different departments. You want to have a historical record of what was running in Google Cloud Platform at any point in time.
What should you do?

  • A. Use Stackdriver to create a dashboard across all projects.
  • B. Use Forseti Security to automate inventory snapshots.
  • C. Use Security Command Center to view all assets across the organization.
  • D. Use Resource Manager on the organization level.

Answer: B

Explanation:
Only Forseti security can have both 'past' and 'present' (i.e. historical) records of the resources. https://forsetisecurity.org/about/


NEW QUESTION # 134
An organization's security and risk management teams are concerned about where their responsibility lies for certain production workloads they are running in Google Cloud Platform (GCP), and where Google's responsibility lies. They are mostly running workloads using Google Cloud's Platform-as-a-Service (PaaS) offerings, including App Engine primarily.
Which one of these areas in the technology stack would they need to focus on as their primary responsibility when using App Engine?

  • A. Encrypting all stored data
  • B. Defending against XSS and SQLi attacks
  • C. Configuring and monitoring VPC Flow Logs
  • D. Manage the latest updates and security patches for the Guest OS

Answer: A


NEW QUESTION # 135
You are a member of the security team at an organization. Your team has a single GCP project with credit card payment processing systems alongside web applications and data processing systems. You want to reduce the scope of systems subject to PCI audit standards.
What should you do?

  • A. Use multi-factor authentication for admin access to the web application.
  • B. Use VPN for all connections between your office and cloud environments.
  • C. Move the cardholder data environment into a separate GCP project.
  • D. Use only applications certified compliant with PA-DSS.

Answer: B

Explanation:
Explanation/Reference: https://cloud.google.com/solutions/pci-dss-compliance-in-gcp


NEW QUESTION # 136
A company's application is deployed with a user-managed Service Account key. You want to use Google-recommended practices to rotate the key.
What should you do?

  • A. Open Cloud Shell and run gcloud iam service-accounts enable-auto-rotate --iam-account=IAM_ACCOUNT.
  • B. Open Cloud Shell and run gcloud iam service-accounts keys rotate --iam-account=IAM_ACCOUNT --key=NEW_KEY.
  • C. Create a new key, and use the new key in the application. Store the old key on the system as a backup key.
  • D. Create a new key, and use the new key in the application. Delete the old key from the Service Account.

Answer: D


NEW QUESTION # 137
A customer's internal security team must manage its own encryption keys for encrypting data on Cloud Storage and decides to use customer-supplied encryption keys (CSEK).
How should the team complete this task?

  • A. Use the gsutil command line tool to upload the object to Cloud Storage, and specify the location of the encryption key.
  • B. Upload the encryption key to a Cloud Storage bucket, and then upload the object to the same bucket.
  • C. Generate an encryption key in the Google Cloud Platform Console, and upload an object to Cloud Storage using the specified key.
  • D. Encrypt the object, then use the gsutil command line tool or the Google Cloud Platform Console to upload the object to Cloud Storage.

Answer: D


NEW QUESTION # 138
Your organization is rolling out a new continuous integration and delivery (CI/CD) process to deploy infrastructure and applications in Google Cloud Many teams will use their own instances of the CI/CD workflow It will run on Google Kubernetes Engine (GKE) The CI/CD pipelines must be designed to securely access Google Cloud APIs What should you do?

  • A. * 1 Create a dedicated service account for the CI/CD pipelines
    * 2 Run the deployment pipelines in a dedicated nodes pool in the GKE cluster
    * 3 Use the service account that you created as identity for the nodes in the pool to authenticate to the Google Cloud APIs
  • B. * 1 Create service accounts for each deployment pipeline
    * 2 Generate private keys for the service accounts
    * 3 Securely store the private keys as Kubernetes secrets accessible only by the pods that run the specific deploy pipeline
  • C. * 1 Create individual service accounts (or each deployment pipeline
    * 2 Add an identifier for the pipeline in the service account naming convention
    * 3 Ensure each pipeline runs on dedicated pods
    * 4 Use workload identity to map a deployment pipeline pod with a service account
  • D. * 1 Create two service accounts one for the infrastructure and one for the application deployment
    * 2 Use workload identities to let the pods run the two pipelines and authenticate with the service accounts
    * 3 Run the infrastructure and application pipelines in separate namespaces

Answer: C


NEW QUESTION # 139
......

Professional-Cloud-Security-Engineer dumps Exam Material with 212 Questions: https://www.braindumpquiz.com/Professional-Cloud-Security-Engineer-exam-material.html

Professional-Cloud-Security-Engineer Questions and Answers Guarantee you Oass the Test Easily: https://drive.google.com/open?id=1WK9O7ikC8xobwYq6C1nV2o2MEkYETZfh